Roam.io
Roam In. Roam Out.

Privacy Policy

DRAFT — LEGAL REVIEW REQUIRED. This text is an implementation draft for product behaviour, not legal advice and not a counsel-approved policy.
Operator: Aman Pareek
Jurisdiction: India
Effective: 2026-09-01
Contact: amanprk4@gmail.com

Data Roam.io uses

Roam.io stores account and profile details such as your display name, username, profile picture, bio, home country, languages, travel pace, traveler types, and interests. Your sign-in email and authentication identities are held by Supabase Auth and are not copied into the public profiles table. If you choose Google sign-in, Google provides Supabase Auth with your Google account identifier, email address, and basic profile information needed to authenticate and initialize your Roam.io profile; Roam.io does not receive your Google password.
Trip data can include destinations, cities, dates, timezone, itinerary days, activities, tasks, task assignees and due dates, shared trip expenses and settlements, notes, booking links, confirmation values, collaboration roles, invitations, and trip history. People sharing a trip can see the content their role permits. Activity history keeps the display-name snapshot captured when an event occurred. Trip expenses stay private to accepted trip members and are not included in Tribe posts.
Inspiration Board data can include a required external source link, title, note, category, source-provider metadata, derived preview image, public/private audience choice, optional trip link, author attribution, likes, private saves, and trip-member votes. Sharing a supported link from another app passes its text or URL into the Roam.io composer for your review; Roam.io does not automatically publish it. Public Ideas and their author profile details can be visible to eligible signed-in travelers, while private ideas stay with the author unless linked to a trip the viewer can access.

Traveler search and friends

Authenticated Roam.io users can search for other travelers by display name or username. Search does not expose your email, trips, location, or credits to unrelated searchers.
Signed-in users can see selected profile pictures, bio, home, languages, and travel personality on search, profiles, friend requests, and Tribe, unless either person has blocked the other. Direct one-to-one messages stay limited to accepted friends. Friends-since dates, shared-trip counts, and friend lists remain friend-only connection details.
A trip owner can select an accepted friend for a collaboration invitation; Roam.io resolves the recipient’s confirmed email only inside the protected invitation service and does not reveal it to the owner. The friend must still accept before receiving trip access. Friendship does not itself grant access to trips, and trip collaboration does not automatically create a friendship. Roam.io does not upload your contact book for matching.
Tribe is an authenticated community feed. Posts, comments and one-level replies, author profile pictures on visible posts, chosen profile details, manually selected place tags, uploaded post photos, and deliberately shared itinerary snapshots can be visible to other eligible signed-in users. Tribe never exposes your sign-in email or private trips. Search terms are used to return matching community content and are not intentionally sent to product analytics. Blocking applies in both directions to Tribe visibility and interaction; reporting a post or comment sends the selected target and the details you provide for private safety review.
The Ideas section is an authenticated link-first community feed. Public ideas can appear in Explore and on the author’s profile, including their source link, preview, title, note, category, author attribution, like count, and save count. Saving another traveler’s idea creates a private copy with source attribution when the original remains visible. Linking or voting on an idea inside a shared trip is visible only to accepted members of that trip. Blocking removes public-idea visibility between the blocked pair without changing access to a trip they still share.

Private messages and safety

Accepted friends can exchange private one-to-one text messages. Trip owners and collaborators can also use a trip group chat shared with everyone who can view that trip. Messages are stored and processed for conversation delivery and are visible only to their participants under application access controls. Roam.io does not offer public messages or contact syncing, and does not claim that messages are end-to-end encrypted.
When you enable push notifications, Roam.io stores an Expo device push token with your account so it can deliver short lock-screen alerts for invitations, collaboration updates, friend requests, messages, and Tribe likes or comments. Push payloads include only a title, a generic summary, and deep-link identifiers—never message text, notes, emails, comment bodies, or booking details. You can turn push and each alert category off in Settings.
Blocking prevents new friendship requests and direct messages in both directions without changing shared trips or trip group chat access. You may report a traveler or a received message for safety review. Reports are not visible to ordinary users, and report details are not included in Realtime broadcasts, push payloads, or application logs.

Photos, maps, and location

Optional trip covers are processed on your device and stored in a private Supabase Storage bucket. Signed links are temporary.
Optional Tribe post photos are stored in a private bucket and are shown through short-lived signed links only when the related post is visible to the viewer. Deleting a post requests best-effort removal of its photo objects. Place tags are entered or selected by you for sharing with that post; do not add a private address or another person’s precise location.
Accepted trip members may upload travel documents and booking files (PDF, JPEG, or PNG) to private application storage. Viewer uploads stay private to the uploader. Editors and owners may keep their uploads private or explicitly mark them Shared with trip, which lets accepted editors and viewers open them. Friendship alone never grants document access. Files may contain sensitive personal information such as booking references or identification details. Roam.io does not use document contents for AI processing in this phase. When a document is newly shared with a trip, collaborators may receive a generic trip update (Inbox Updates and optional collaboration push) that never includes file contents, filenames, titles, notes, or signed links. Document rows are also excluded from Realtime payloads and application logs. Opening or saving a copy may place a file under operating-system or user control outside Roam.io. Files are removed when a document is deleted, when the owning trip is deleted, or when its uploader deletes their account, subject to documented best-effort object cleanup and retry behaviour. Roam.io does not claim end-to-end encryption of stored files, malware scanning, or guaranteed secure deletion from every backup.
Geocoding runs only after an explicit foreground action. Roam.io can hand a place to an external maps app. An in-app journey preview uses Apple Maps on iOS, Google Maps on Android when a Maps SDK key is configured, and Google Maps on web when a Maps JavaScript key is configured; otherwise the city-to-city route list is shown. Showing that preview can send coordinates and map-tile requests to Apple or Google. Roam.io does not continuously track location and does not request background location tracking.

Preferences and device storage

Appearance, language, currency, time format, map choice, trip pace, dietary defaults, AI defaults, and collapsed Trip Details sections may be stored on your device. Notification category preferences and push tokens are stored with your account so alerts can respect your choices when the app is closed. Preferred region, age-eligibility confirmation, legal acceptances, and privacy-request records may also be stored with your account. The last successful legal and privacy snapshot may also be cached on this device so the app can open without a network; that cache is cleared on sign-out or account deletion. You may also save up to five trips for offline, read-only use on this device (itinerary, tasks, expenses, and—on iOS/Android—document files for those trips); manage them from Profile or Settings → Offline trips. That offline data refreshes when you open a saved trip online and is cleared on sign-out, account switch, unpin, or account deletion. Roam.io Credits usage and completed generation history are stored with your account so the service can enforce daily limits and show your usage.
While you create a Tribe post, its text, selected place tags, and selected itinerary identifier may be saved locally on your device under your signed-in account so an unfinished draft can be restored. Draft photos are not persisted and must be selected again. Local Tribe drafts and recent searches are not sent to analytics and are cleared when you publish, sign out, or delete your account.

Analytics and performance

Optional privacy-safe product analytics start only after you opt in from Privacy & Data (or during signup). Native performance and product signals use Expo EAS Observe, which starts with dispatch disabled. On web, Roam.io also measures the standard CLS, FCP, INP, LCP, and TTFB browser metrics and sends only the metric name, numeric value and delta, rating, random per-metric identifier, navigation type, coarse viewport size, app version, and a route pattern with dynamic identifiers removed to a Supabase Edge Function. The function writes that fixed payload to restricted operational logs for aggregate performance review. There is no expo-insights client in the app; any EAS Update Insights aggregation that may exist from Update hosting is separate from account-scoped product analytics.
Roam.io does not intentionally send account identifiers, trip or itinerary content, resolved route identifiers, query strings, messages, documents, booking information, Tribe search queries, posts, comments, image or location details, AI prompts or outputs, emails, usernames, display names, user-agent strings, or other user-entered text in analytics payloads. Service providers may still process ordinary request metadata such as an IP address under their infrastructure terms. Expo “users” are anonymous installations and are not the same as verified Roam.io accounts or App Store / Play Store download figures. The app does not detect uninstalls; download and uninstall statistics come from Apple App Store Connect and Google Play Console. Analytics failures never block normal use. Turning analytics off disables further Observe and Web Vitals dispatch for that account session. Roam.io does not claim complete anonymity beyond provider documentation, end-to-end encryption of analytics, zero retention, exact deletion of provider-side aggregated analytics after account deletion, or that analytics identify unique human beings.

AI-assisted planning

Authenticated owners and editors may ask a server-side Edge Function for city or activity suggestions. The relevant trip context and the planning preferences you enter are sent to OpenAI to generate the requested draft. Do not include passport numbers, payment details, medical records, or other unnecessary sensitive information in AI prompts or trip notes. Suggestions are saved only after review and explicit acceptance.
Minimal operational audit rows can record the user, trip, action, model, status, request identifier, token counts, credit usage, web-search use, and safe error code. Prompts, generated drafts, preferences, notes, booking information, confirmations, exact addresses, tokens, sessions, and API keys are deliberately excluded from AI audit rows and shared activity metadata.

Sharing and service providers

Supabase provides authentication, database, private storage, Realtime updates, Edge Functions, and the consent-gated Web Vitals log receiver described in Analytics and performance. Google acts as an identity provider only when you choose Google sign-in, and supplies the authentication data described above to Supabase Auth. OpenAI processes AI planning requests. Apple Maps (iOS) and Google Maps (Android and web, when the journey preview is shown) may process map tiles and coordinates for that preview. External geocoding and map applications process searches you explicitly request. A configured transactional email provider may deliver invitations and service messages. Expo provides application distribution tooling plus optional consent-gated performance monitoring (EAS Observe). Roam.io may also request the public App Store or Play Store listing for this app to compare the installed version with the latest published version; that request uses the app identifier only—not your account, trips, or other personal details.
When push notifications are enabled, Expo receives device push tokens and routes lock-screen alerts through Apple Push Notification service (APNs) on iOS and Firebase Cloud Messaging (FCM) on Android. Those platform services process delivery metadata needed to reach your device.
These providers may process information in countries other than your own under their applicable contractual and legal safeguards. Row Level Security, private storage, and server-side authorization restrict access, but no system can promise absolute security or uninterrupted availability. Roam.io does not sell traveler profiles, friendship data, trip content, or contact information.

Retention and deletion

Account, profile, trip, friendship, collaboration, messaging, Tribe posts and comments, Inspiration Board items and interactions, notification preferences, push tokens, uploaded trip documents, and preference data remain while needed to provide the service. Operational, abuse-prevention, security, and audit records are retained only for as long as reasonably needed for those purposes or as required by law. Deleting an account removes its uploaded trip documents and, for an owner, its owned trips and dependent content, plus authored Tribe posts, comments, likes, snapshots, Inspiration items, idea likes, saves, votes, and post-image objects when cleanup succeeds. Memberships in other owners’ trips, friend requests, accepted friendships, traveler blocks, read markers, notification preferences, push tokens, and traveler profile data are removed with the account.
Removing a friendship does not delete previous messages; the conversation becomes read-only until friendship is restored. After account deletion, previously delivered messages may remain for the surviving participant, but the deleted sender’s name, username, email, and profile are removed and replaced with “Former traveler”. Safety reports may be retained with deleted-account identity minimized. Historical shared-trip events use the same Former traveler treatment. Private owned-trip covers and trip-document objects are removed before deletion is finalized when storage cleanup succeeds, with documented best-effort retry behaviour for orphaned objects.

Your choices and requests

You can edit profile and preference information, change your username, remove connections, leave shared trips where permitted, turn push notifications and alert categories off in Settings, manage optional analytics and preferred region under Privacy & Data, submit privacy requests in the app, and delete your account from Settings. Contact the privacy address shown with this policy to request access, correction, deletion, or other rights available under applicable law. Immediate in-app account deletion remains available separately from privacy-request workflows. Roam.io may need to verify requests before acting on them.

Age and policy updates

Roam.io is for people who are 18 or older. Do not create an account if you are under 18. Roam.io does not store a date of birth; eligible users confirm an age bracket only. Material privacy changes will be reflected by updating the effective date and, when appropriate, providing an in-app notice.